Recruitment|New Graduate

Job Overview

The role of an engineer at Cyber Defense Institute (CDI) is not about simply running tools or working through checklists.
Our mission spans every layer, from the physical layer to the application layer, and even the psychology of people within organizations. Rather than being bound by existing methods or industry conventions, we identify the true nature of each challenge and use exceptional technical skill and creativity to arrive at the optimal solution, exceeding our clients' expectations.

Your Work After Joining

New graduates who join us will, based on the strengths and interests identified through the interview process, begin by gaining hands‑on experience in one of the following areas.

Penetration Testing
Red Team Testing
Hardware Security
Reverse Engineering / Exploit Development
Web Application Security Testing
Threat Intelligence

To help companies and organizations strengthen their security, we take on the mindset and perspective of an attacker to test their defenses and provide advice for improvement.
We carry out simulated attacks against target systems to determine whether intrusion, data theft, or a given attack objective can be achieved.
In the process, we identify the information assets, vulnerabilities, and intrusion paths that could be exploited in an attack, and report these findings to the client.

While penetration testing primarily verifies whether an attack such as intrusion or data theft can succeed, and identifies the information assets, vulnerabilities, and intrusion paths involved, Red Team testing goes further: it carries out a variety of attacks based on scenarios tied to the objectives of the engagement.
This not only tests whether an attack can succeed, but also provides insight into the organization's detection, investigation, and incident‑response capabilities from the perspective of people, process, and technology.

We conduct multi‑faceted security assessments targeting the physical and network layers of a wide range of devices, including circuit boards, debug interfaces, and wired/wireless communications.
Through disassembling devices, observing signals, analyzing communications, performing reverse engineering, and developing custom attack tools and test fixtures, we uncover vulnerabilities and design flaws that could lead to information leakage, tampering, or unauthorized manipulation.

We analyze everything from applications to firmware in order to discover and demonstrate vulnerabilities that exist at the implementation level of a system.
By reverse engineering the target binaries to understand their internal structure and behavior, and by developing exploits for the vulnerabilities we uncover, we technically clarify the conditions required for an attack to succeed and the scope of its impact.

For web applications and websites, we gain a deep understanding of the system's specifications and business logic, then perform multi‑faceted security assessments from an attacker's perspective.
Beyond simply checking for vulnerabilities using the latest attack techniques, we analyze how discovered vulnerabilities could be combined into a viable attack scenario, revealing the true business impact and identifying which issues should be prioritized for remediation.

Building on reverse‑engineering techniques, we solve challenges related to topics such as APTs, threat intelligence, malware analysis, attribution, and active cyber defense.
Our work ranges from threat research on specific topics, to client advisory services, to product development.

Who We're Looking For

We are not simply looking for people with high skill levels. What we need are individuals with truly distinctive personalities—the kind of outliers who stand apart statistically. Here are some examples.

An Insatiable Technical Curiosity

A strong drive to understand existing technologies, refusing to stop analyzing until you fully understand and are satisfied with how something works.

A Hacker's Mindset

No matter how robust a system appears, you find the smallest gap in its structure, and never stop thinking until you overturn the situation through your own intelligence and persistence.

Autonomous Thinking, Transcendent Results

Rather than waiting for instructions, you define your own challenges and see hypothesis testing and research through to completion on your own. You also strive to deliver results that go beyond what the client expects.

A Willingness to Take On New Domains

Rather than confining yourself to your own area of expertise, you remain flexible enough to continually take on new domains. In the process, you put what you learn into words, share it with others, and act with the organization's overall benefit in mind.

Even if your strengths aren't described above, if you have something unique to offer, we'd love to hear from you. Have you ever found yourself researching something late at night simply because you were curious, with no one asking you to? If so, we encourage you to apply.

What You'll Gain Through This Work

01

An Environment Where You Can Learn Alongside Top Engineers

You'll work alongside a diverse group of engineers who are at the forefront of their respective fields.

02

The Freedom to Expand Your Own Expertise

At CDI, there's a culture of continually expanding your area of expertise on your own initiative.

03

A Hacker's Mindset

Walls exist to be overcome. You'll have colleagues who never stop thinking. While day‑to‑day work often means running into difficult obstacles, each time you hit a wall, you build the skill of finding a way through it.

04

Boundless Opportunities to Make an Impact

At CDI, there's no need to stay within the confines of your assigned role—the more you identify challenges and act on your own initiative, the more you'll shine. Your thinking and actions directly become value.

05

Experiences Beyond the Ordinary

Your work as an engineer isn't limited to assessment work alone; it can extend in unexpected directions, from speaking at international conferences to serving as a technical advisor for TV dramas.

A Picture of Your First Year

Even as a new graduate, we support each person's growth so that you can start contributing in a frontline environment as early as possible. (Note: the pace of growth and the timing of role changes vary by individual.)

Learning the CDI Culture

Through on‑the‑job training with senior engineers, you'll learn CDI's unique tools, methods, and culture while supporting real client engagements.

~ 3 months
3~6months
Participating in Real Engagements

You'll join real projects as a team member, experiencing the process of delivering value to clients by supporting reporting and client presentations. At the same time, you'll begin considering the direction of your own area of expertise.

Leading Engagements and Deepening Your Technical Skills

You'll take on more opportunities to lead engagements, including client communication and delivering reports, while continuing to deepen your own expertise.

6~12months
1year~
Growing as a CDI Engineer

You'll continue to sharpen your expertise in a specific field, while growing into someone who demonstrates CDI's technical capabilities externally through research, conference presentations, CVE assignments, and academic papers.


Must

Required Skills

  • Strong ethics and a sense of responsibility as a security engineer, including the ability to maintain confidentiality
  • Ability to logically analyze and explain observations based on an experimental approach
  • Ability to clearly communicate technical content in an accessible way
  • Ability to independently define challenges and proceed autonomously through hypothesis testing and research
Welcome

Preferred Experience

  • Strong ethics and a sense of responsibility as a security engineer, including the ability to maintain confidentiality
  • Award‑winning results or challenge‑authoring experience in CTFs or competitive programming
  • Experience sharing knowledge through conference talks, technical blog writing, and similar activities
  • Internship experience at a security company
  • Certifications in offensive security or cloud security
  • A track record of CVE assignments or contributing security patches to open‑source projects
  • Experience conducting research and writing academic papers

Employment Conditions

Employment type Full-time employee
6-month probationary period (no changes to working conditions during this period)
Location Ochanomizu First Building 5F, 2-5-1, Kanda Surugadai, Chiyoda-ku, Tokyo, Japan, 101-0062
Smoking Policy Indoor smoking is permitted in designated areas
Working Hours
  • Flextime system
  • Standard working hours: 8 hours per day
  • Core hours: 11:00 AM – 2:00 PM
Working Style This is a hybrid position based in Tokyo.
While remote work is available depending on the project and team situation, regular attendance at the Tokyo office is required. Please note that all applicants must currently reside in Japan.
Holidays and Leave
  • 122 annual holidays
  • Complete two-day weekends (Saturdays and Sundays)
  • National holidays
  • Year-end and New Year holidays
  • Substitute holidays for national holidays falling on a Saturday
  • Paid leave: 20 to 22 days per year
  • Family-friendly leave (including marriage leave, maternity/paternity leave, prenatal checkup leave, childcare leave, child nursing leave, caregiving leave, bereavement leave, etc.)
Social Insurance
  • Employment Insurance
  • Health Insurance
  • Employees' Pension Insurance
  • Workers' Accident Compensation Insurance
Visa Requirements Applicants must be eligible to work in Japan.
While the company does not cover visa application fees or related costs, we will provide necessary documents and support required for the visa application process.
Benefits and Welfare
  • Defined contribution pension plan (401K)
  • Commuting allowance (according to company policy)
  • Housing allowance (according to company policy)
  • Payroll savings program ("Zaikei," a Japanese asset-formation savings scheme funded through payroll deduction), with additional contributions matched by the company
  • Support for obtaining professional certifications
  • Discounted rates for various insurance products
  • Congratulatory and condolence allowance
  • Flexible benefits program, administered through third-party welfare service providers (Relo Club, Benefit One)
  • Free office drinks
  • Many unofficial employee clubs (voluntary participation)
  • Employee Bug Bounty Program
Employment type
Full-time employee
6-month probationary period (no changes to working conditions during this period)
Location
Ochanomizu First Building 5F, 2-5-1, Kanda Surugadai, Chiyoda-ku, Tokyo, Japan, 101-0062
Smoking Policy
Indoor smoking is permitted in designated areas
Working Hours
  • Flextime system
  • Standard working hours: 8 hours per day
  • Core hours: 11:00 AM – 2:00 PM
Working Style
This is a hybrid position based in Tokyo.
While remote work is available depending on the project and team situation, regular attendance at the Tokyo office is required. Please note that all applicants must currently reside in Japan.
Holidays and Leave
  • 122 annual holidays
  • Complete two-day weekends (Saturdays and Sundays)
  • National holidays
  • Year-end and New Year holidays
  • Substitute holidays for national holidays falling on a Saturday
  • Paid leave: 20 to 22 days per year
  • Family-friendly leave (including marriage leave, maternity/paternity leave, prenatal checkup leave, childcare leave, child nursing leave, caregiving leave, bereavement leave, etc.)
Social Insurance
  • Employment Insurance
  • Health Insurance
  • Employees' Pension Insurance
  • Workers' Accident Compensation Insurance
Visa Requirements
Applicants must be eligible to work in Japan.
While the company does not cover visa application fees or related costs, we will provide necessary documents and support required for the visa application process.
Benefits and Welfare
  • Defined contribution pension plan (401K)
  • Commuting allowance (according to company policy)
  • Housing allowance (according to company policy)
  • Payroll savings program ("Zaikei," a Japanese asset-formation savings scheme funded through payroll deduction), with additional contributions matched by the company
  • Support for obtaining professional certifications
  • Discounted rates for various insurance products
  • Congratulatory and condolence allowance
  • Flexible benefits program, administered through third-party welfare service providers (Relo Club, Benefit One)
  • Free office drinks
  • Many unofficial employee clubs (voluntary participation)
  • Employee Bug Bounty Program

Selection Process

Step. 1 Casual Interview (Optional)

An informal conversation, offered before the formal document screening.

Step. 2 Document Screening

Please submit your resume, work history (CV), and portfolio. Based on the materials you provide, we will comprehensively review your background, skills, and motivation for applying.
We will typically notify you of the results of the document screening by email within one to two weeks.

Step. 3 Aptitude Test

We conduct a standardized aptitude test (commonly used in Japanese hiring, known as the SPI test).
This is used as an opportunity for us to get to know each other from a perspective distinct from technical skills and experience.

Step. 4 First Interview

We will ask about your past experience, your approach to work, and your reasons for wanting to join our company, using this as an opportunity to deepen mutual understanding.

Step. 5 Technical Assessment + Second Interview

Based on the results of the first interview, this stage discusses in more concrete terms your fit with the team and suitability for the actual work involved.

Step. 6 Final Interview

This interview is conducted by a member of our executive management or board of directors. We will share our company's vision and future direction while confirming final mutual intent.
We aim to proceed carefully so that both parties can reach a mutual understanding and start off on a positive note.

※Please note that the selection process may vary depending on the position and the status of applications.

How to Apply

To apply, please agree to our Privacy Policy and contact us using the application form below.We will get back to you shortly.
Please note that we do not accept inquiries related to recruitment by phone.